CVE-2025-46631

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.
Configurations

No configuration.

History

02 May 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-287

02 May 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Los controles de acceso inadecuados en el portal de administración web del Tenda RX2 Pro 16.03.30.14 permiten que un atacante remoto no autenticado habilite el acceso telnet al sistema operativo del enrutador mediante el envío de una solicitud web /goform/telnet.

01 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 20:15

Updated : 2025-05-02 15:15


NVD link : CVE-2025-46631

Mitre link : CVE-2025-46631

CVE.ORG link : CVE-2025-46631


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication